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This listing of claims will replace all prior versions, and listings, of claims in the application. 
Listing of Claims: 

1 . (Currently Amended) A method for a user at a second computing 
device to render r e nd e ring encrypted digital content on a first computing device distinct from 
the second device, the first device having a public key (PU1) and a corresponding private key 
(PR1), the second device having a public key (PU2) and a corresponding private key (PR2), 
the digital content being encrypted according to a content key (KD), the method comprising: 

the user at the second device obtaining from a licensor distinct from the 
second device a digital license corresponding to the content and the second device, the digital 
license including the content key (KD) therein in an e ncrypt e d form encrypted according to 
the public key (PU2) of the second device (PU2 (KD)), and also including rules for 
determining whether the license permits issuance of a sub-license from the second device to 
the first device ; 

the user at the second device determining that the rules of the license do in fact 
permit issuance of a sub-license from the second device to the first device; 

the user at the second device decrypting th e e ncrypted cont e nt k e y (KD) (PU2 
(KD)) from the digital license with the corresponding private key (PR2) to produce the 
content key (KD); 

the user at the second device obtaining from the first device the public key 

thereof (PU1); 

the user at the second device encrypting the content key (KD) according to the 
public key (PU1) of the first device (PU1 (KD)); and 
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the user at the second device composing [[a]] the sub-license corresponding to 
and based on the obtained license for the first device, the sub-license including (PU1 (KD)) 5 
and transferring the composed sub-license to the first device, wherein the first device can 
decrypt (PU1 (KD)) with the private key thereof (PR1) to produce the content key (KD), and 
can render the encrypted content on the first device with the produced content key (KD). 



2. (Original) The method of claim 1 further comprising, prior to 
composing the sub-license and transferring the composed sub-license to the device, checking 
the obtained license to determine that such license permits issuance of the sub-license to the 
device. 

3. (Original) The method of claim 1 further comprising transferring 
the content to the first device. 

4. (Original) The method of claim 1 for rendering encrypted digital 
content on a first device having a digital rights management (DRM) system, the DRM system 
having the public key (PU1) and the corresponding private key (PR1), the method 
comprising: 

obtaining from the first device the public key of the DRM system thereof 

(PU1); 

encrypting the content key (KD) according to the public key (PU1) of the 
DRM system of the first device (PU1 (KD)); and 
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composing a sub-license corresponding to and based on the obtained license, 
the sub-license including (PU1 (KD)), and transferring the composed sub-license to the first 
device, wherein the DRM system of the first device can decrypt (PU1 (KD)) with the private 
key thereof (PR1) to produce the content key (KD), and can render the encrypted content on 
the first device with the produced content key (KD). 



5. (Original) The method of claim 1 comprising: 

obtaining the digital license and storing the obtained digital license on a 

second device; 

decrypting the encrypted content key (KD) from the digital license on the 
second device to produce the content key (KD); 

obtaining from the first device the public key thereof (PU1); 

encrypting the content key (KD) according to the public key (PU1) of the first 
device (PU1 (KD)); and 

composing a sub-license corresponding to and based on the obtained license, 
the sub-license including (PU1 (KD)), and transferring the composed sub-license from the 
second device to the first device, wherein the first device can decrypt (PU1 (KD)) with the 
private key thereof (PR 1) to produce the content key (KD), and can render the encrypted 
content on the first device with the produced content key (KD). 

6. (Original) The method of claim 5 wherein the second device has a 
public key (PU2) and a corresponding private key (PR2), the method comprising: 
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obtaining a digital license corresponding to the content, the digital license 
including the content key (KD) encrypted according to the public key (PU2) of the second 
device (PU2 (KD)); and 

decrypting (PU2(KD)) from the digital license according to the private key 
(PR2) of the second device to produce the content key (KD). 



7. (Original) The method of claim 5 wherein the second device is a 



computer. 



8. (Original) The method of claim 1 wherein, the first device is a 



portable device. 



9. (Original) The method of claim 1 wherein obtaining from the first 
device the public key thereof (PU1) comprises receiving a certificate from the first device 
within which is (PU1). 



10. (Original) The method of claim 9 further comprising comparing 
the received certificate against a revocation list to ensure that the certificate has not been 
compromised. 



1 1 . (Original) The method of claim 9 comprising receiving a 
certificate from the first device within which is (PU1) and information relating to the first 
device. 
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12. (Original) The method of claim 1 1 further comprising, prior to 
composing the sub-license and transferring the composed sub-license to the device, checking 
the obtained license to determine that such license permits issuance of the sub-license to the 
device, such checking including employing the information relating to the first device to 
determine whether the license permits issuance of the sub-license. 

13. (Original) The method of claim 1 1 comprising receiving a 
certificate from the first device within which is (PU1) and information relating to at least one 
of the name, type, and manufacturer of the first device. 

14. (Original) The method of claim 1 further comprising obtaining 
(PU1 (KD)) from the transferred sub-license, applying (PR1) to (PU1 (KD)) to obtain the 
content key (KD), and applying (KD) to decrypt the encrypted content, all by the first device. 

1 5 . (Currently Amended) A method for a user at first and second devices 
to r e nd e ring render encrypted digital content on a first device computing having a public key 
(PU1) and a corresponding private key (PR1) by way of a second device distinct from the 
first device, the t second device having a public key CPU2) and a corresponding private key 
fPR2). the digital content being encrypted according to a content key (KD), the method 
comprising: 

providing th e public k e y (PU1) to a oooond d e vic e , wh e r e in th e o e cond d e vic e 
obtains a digital lic e ns e corr e sponding to th e cont e nt, th e digital lic e ns e including tho contont 
koy (KD) th e r e in in an e ncryptod form, d e crypts th e e ncrypt e d cont e nt k e y (KD) from tho 
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digital lic e ns e to produc e th e cont e nt k e y (KB), e ncrypts th e content k e y (KD) according to 
th e public k e y (PU1) of th e first d e vic e (PU1 (KB)), and composes a sub liconso 
corresponding to and bas e d on th e obtain e d lic e ns e , th e sub lic e ns e including (PU1 (KB)); 

the user at the second device obtaining from a licensor distinct from the 
second device a digital license corresponding to the content and the second device, the digital 
license including the content key (KD) therein encrypted according to the public key (FU2) 
of the second device (PU2 (KD)), and also including rules for determining whether the 
license permits issuance of a sub-license from the second device to the first device; 

the user at the second device determining that the rules of the license do in fact 
permit issuance of a sub-license from the second device to the first device; 

the user at the second device decrypting (PU2 (KD)) from the digital license 
with the corresponding private key (PR2) to produce the content key (KD); 

the user at the second device obtaining from the first device the public key 

thereof (PUD; 

the user at the second device encrypting the content key (KD) according to the 
public key (PUD of the first device (PU1 (KD)); and 

the user at the second device composing the sub-license corresponding to and 
based on the obtained license for the first device, the sub-license including (PU1 (KD)). and 
transferring the composed sub-license to the first device; 

the user at the first device receiving the composed sub-license from the second 

device; 

the user at the first device obtaining (PU1 (KD)) from the received sub- 
license; 
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the user at the first device applying (PR1) to (PU1 (KD)) to obtain the content 

key (KD); 

the user at the first device applying (KD) to decrypt the encrypted content; and 
the user at the first device rendering the decrypted content. 

16. (Original) The method of claim 15 further comprising receiving 
the content from the second device. 

17. (Original) The method of claim 15 for rendering encrypted digital 
content on a first device having a digital rights management (DRM) system, the DRM system 
having the public key (PU1) and the corresponding private key (PR1), the digital content 
being encrypted according to a content key (KD), the method comprising: 

providing the public key (PU1) of the DRM system to the second device; 
receiving the composed sub-license from the second device; 
obtaining (PU1 (KD)) from the received sub-license; 

applying the private key (PR1) of the DRM system to (PU1 (KD)) to obtain 
the content key (KD); 

applying (KD) to decrypt the encrypted content; and 
rendering the decrypted content. 

18. (Original) The method of claim 15 wherein the second device is a 

computer. 
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19. (Original) The method of claim 15 wherein, the first device is a 
portable device. 

20. (Original) The method of claim 15 wherein providing the public 
key (PU1) to the second device comprises providing a certificate to the second device within 
which is (PU1). 



key (PU1) to the second device comprises providing a certificate to the second device within 
which is (PU1) and information relating to the first device, wherein the second device can 
employ the information relating to the first device to determine whether the obtained license 
permits issuance of the sub-license. 

22. (Original) The method of claim 21 comprising providing the 
certificate to the second device within which is (PU1) and information relating to at least one 
of the name, type, and manufacturer of the first device. 



21. 



(Original) 



The method of claim 20 wherein providing the public 



23. 



(Withdrawn) A method of checking out a sub-license to a first device 



from a second device comprising: 



receiving a request from the second device for a nonce, and providing such 



nonce; 



receiving from the second device the checked-out sub-license and the provided 



nonce; 
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concluding that the nonce received is the same nonce provided; 



therefore concluding that the received sub-license is legitimate; and 



storing the sent sub-license. 



24. (Withdrawn) The method of claim 23 in combination with a method 
of checking in the checked-out sub-license comprising deleting the checked-out sub-license 
and then providing a trusted indication to the second device that the checked-out sub-license 
has in fact been deleted. 

25. (Withdrawn) The method of claim 24 wherein the second device adds 
the checked-out sub-license to a catalog by adding an entry including an identifier identifying 
the checked-out sub-license and an identifier identifying the first device to the catalog, and 
wherein checking in the checked-out sub-license comprises: 

requesting a nonce from the second device, and receiving such nonce; and 
sending to the second device the received nonce, an identifier identifying the 
first device, and a list of all sub-licenses currently resident on the first device, wherein the 
deleted checked-out sub-license is not in the sent list, and wherein the second device 
concludes that the nonce sent by the first device is the same nonce received by the first 
device, therefore concludes that the sent identifier and list that accompanied the sent nonce is 
legitimate, compares the sent list with the catalog and notes that the deleted checked-out sub- 
license is in the catalog but not on the sent list, and deletes the entry having the identifier 
identifying the deleted checked-out sub-license and the identifier identifying the first device 
from the catalog. 
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26. (Withdrawn) A method of checking out a sub-license from a second 
device to a first device comprising: 

requesting a nonce from the first device, and receiving such nonce; and 
sending the checked-out sub-license and the received nonce to the first device, 
wherein the first device concludes that the nonce sent by the second device is the same nonce 
received by the second device, therefore concludes that the sent sub-license that accompanies 
the sent nonce is legitimate, and stores the sent sub-license. 

27. (Withdrawn) The method of claim 26 further comprising adding the 
checked-out sub-license to a catalog. 

28. (Withdrawn) The method of claim 27 wherein adding the checked- 
out sub-license to the catalog comprises adding an entry including an identifier identifying 
the checked-out sub-license and an identifier identifying the first device to the catalog. 

29. (Withdrawn) The method of claim 27 in combination with a method 
of checking in the checked-out sub-license comprising receiving a trusted indication from the 
first device that the checked-out sub-license has been deleted. 



30. 



(Withdrawn) The method of claim 29 wherein checking in the 



checked-out sub-license comprises: 



receiving a request from the first device for a nonce, and providing such 



nonce; 
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receiving from the first device the provided nonce, an identifier identifying the 
first device, and a list of all sub-licenses currently resident on the first device, wherein the 
deleted checked-out sub-license is not in the sent list; 

concluding that the received nonce is the same nonce provided; 

therefore concluding that the received identifier and list is legitimate; 

comparing the received list with the catalog, and noting that the deleted 
checked-out sub-license is in the catalog but not on the sent list; and 

deleting the entry having the identifier identifying the deleted checked-out 
sub-license and the identifier identifying the first device from the catalog. 



3 1 . (Withdrawn) A method of checking out a sub-license from a second 
device to a first device comprising: 

requesting, by the second device, a nonce from the first device, and receiving 

such nonce; 

sending, by the second device, the checked-out sub-license and the received 
nonce to the first device; 

concluding, by the first device, that the nonce sent by the second device is the 
same nonce received by the second device; 

therefore concluding, by the first device, that the sent sub-license that 
accompanies the sent nonce is legitimate; and 

storing, by the first device, the sent sub-license. 
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32. (Withdrawn) The method of claim 3 1 further comprising adding, by 



the second device, the checked-out sub-license to a catalog. 



33. (Withdrawn) The method of claim 32 wherein adding the checked- 
out sub-license to the catalog comprises adding an entry including an identifier identifying 
the checked-out sub-license and an identifier identifying the first device to the catalog. 



34. (Withdrawn) The method of claim 32 in combination with a method 
of checking in the checked-out sub-license comprising deleting the checked-out sub-license 
from the first device and then providing a trusted indication to the second device that the 
checked-out sub-license has in fact been deleted. 

35. (Withdrawn) The method of claim 34 wherein checking in the 
checked-out sub-license comprises: 

deleting, by the first device, the checked-out sub-license therefrom; 
requesting, by the first device, a nonce from the second device, and receiving 

such nonce; 

sending, by the first device to the second device, the received nonce, an 
identifier identifying the first device, and a list of all sub-licenses currently resident on the 
first device, wherein the deleted checked-out sub-license is not in the sent list; 

concluding, by the second device, that the nonce sent by the first device is the 
same nonce received by the first device; 
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therefore concluding, by the second device, that the sent identifier and list that 
accompanied the sent nonce is legitimate; 

comparing, by the second device, the sent list with the catalog, and noting that 
the deleted checked-out sub-license is in the catalog but not on the sent list; and 

deleting, by the second device, the entry having the identifier identifying the 
deleted checked-out sub-license and the identifier identifying the first device from the 
catalog. 
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